Back to cases

TikTok Technology Limited · European Union / Ireland

TikTok Irish DPC fine: China access and transfer transparency risk

Ireland's Data Protection Commission imposed a EUR 530 million fine focused on safeguards and transparency for EEA user data accessed from or transferred to China.

Industry: Digital platformStatus: enforcedUpdated: Jun 26, 2026
Data, cybersecurity, and AI governance

Facts

The regulator found TikTok had not shown that EEA user personal data transferred to China received protection essentially equivalent to EU law and ordered remediation.

Compliance lessons

Cross-border data projects need regulator-ready proof of data location, access actors, transfer mechanisms, supplementary safeguards, and access logs, not only a privacy policy.

Legal issues

  • GDPR跨境传输 / GDPR transfers
  • 透明度 / transparency
  • 远程访问 / remote access

Sources